Cloudflare Tunnel 主机名路由 GA,初始解析 IP 默认改公网段
Cloudflare Tunnel, Cloudflare Tunnel for SASE, Cloudflare Mesh, Gateway, Cloudflare One - Hostname routing is now generally available, with a new public IP range for initial resolved IPs
使用 Cloudflare Tunnel 或 Gateway 的读者注意:初始解析 IP 默认段已改为公网段,若依赖旧 CGNAT 段或 Chrome 企业策略绕过,需在浏览器更新前调整配置,否则主机名路由可能静默失效。
Hostname routing ↗ is now generally available. Instead of managing static IP lists and routes, you can route traffic by hostname across multiple Cloudflare One connectors:
主机名路由 ↗ 现已正式可用。无需管理静态 IP 列表和路由,您可以通过主机名跨多个 Cloudflare One 连接器路由流量:
- Cloudflare Tunnel: route a private hostname (for example, wiki.internal.local) to a private application behind your tunnel, or a public hostname (for example, bank.example.com) to egress through a specific tunnel and anchor traffic to a dedicated exit node.
- Cloudflare Mesh: attract a private or public hostname's traffic to a Mesh node.
- Cloudflare Tunnel:将私有主机名(例如 wiki.internal.local)路由到隧道后面的私有应用程序,或将公共主机名(例如 bank.example.com)通过特定隧道出口,并将流量锚定到专用出口节点。
- Cloudflare Mesh:将私有或公共主机名的流量吸引到 Mesh 节点。
Alongside GA, the default IPv4 range used for initial resolved IPs (also called token IPs) is changing from a Carrier-Grade NAT (CGNAT) range to a public Cloudflare-owned range:
随着正式发布,用于初始解析 IP(也称为令牌 IP)的默认 IPv4 范围将从运营商级 NAT(CGNAT)范围更改为公共 Cloudflare 拥有的范围:
- IPv4: 172.64.128.0/20
- IPv6: 2606:4700:0cf1:4000::/64
- IPv4:172.64.128.0/20
- IPv6:2606:4700:0cf1:4000::/64
This is the default range. You can configure a custom initial resolved IP range for IPv4 if it conflicts with your existing network.
这是默认范围。如果 IPv4 与您现有网络冲突,您可以配置自定义的初始解析 IP 范围。
Why this is changing: Starting with Chrome 142 ↗, Local Network Access (LNA) restrictions block background requests to CGNAT addresses (100.64.0.0/10), which included the previous initial resolved IP default (100.80.0.0/16). LNA is implemented at the Chromium engine level, so it affects all Chromium-based browsers (for example, Microsoft Edge, Brave, and Opera), not only Google Chrome. This could silently break hostname-based Gateway features for users of these browsers, and required Chrome Enterprise policy workarounds. The new default range is public Cloudflare address space, so it is not affected by this restriction.
变更原因:从 Chrome 142 ↗ 开始,本地网络访问(LNA)限制会阻止对 CGNAT 地址(100.64.0.0/10)的后台请求,其中包括之前的初始解析 IP 默认值(100.80.0.0/16)。LNA 在 Chromium 引擎级别实现,因此它影响所有基于 Chromium 的浏览器(例如 Microsoft Edge、Brave 和 Opera),而不仅仅是 Google Chrome。这可能会静默破坏这些浏览器用户基于主机名的 Gateway 功能,并且需要 Chrome 企业策略变通方法。新的默认范围是公共 Cloudflare 地址空间,因此不受此限制的影响。
What is affected: Initial resolved IPs are used by several features that associate a DNS query with the network connection that follows it:
受影响的内容:初始解析 IP 被多个功能使用,这些功能将 DNS 查询与后续的网络连接关联起来:
- Private and public hostname routing for Cloudflare Tunnel
- Hostname routes for Cloudflare Mesh
- Access private applications on non-HTTPS ports
- Egress policy host selectors (Domain, Host, Application, and Content Categories)
- Cloudflare Tunnel 的私有和公共主机名路由
- Cloudflare Mesh 的主机名路由
- 通过非 HTTPS 端口访问私有应用程序
- 出口策略主机选择器(域、主机、应用程序和内容类别)
You can check your account's current range, or configure a custom range, at any time from Zero Trust > Team & Resources > Devices > Device profiles, or using the Initial Resolved IP Subnet API.
您可以随时通过 Zero Trust > Team & Resources > Devices > Device profiles 或使用 Initial Resolved IP Subnet API 检查您账户的当前范围,或配置自定义范围。
For full instructions, refer to Configure initial resolved IPs. The IPv6 range (2606:4700:0cf1:4000::/64) is unchanged and is not affected by this restriction.
有关完整说明,请参阅配置初始解析 IP。IPv6 范围(2606:4700:0cf1:4000::/64)保持不变,不受此限制的影响。
If you were relying on a Chrome Enterprise policy workaround (such as LocalNetworkAccessRestrictionsTemporaryOptOut) while your account was still on the legacy CGNAT-based range, refer to Google Chrome restricts access to private hostnames for next steps.
如果您在账户仍使用旧版基于 CGNAT 的范围时依赖 Chrome 企业策略变通方法(例如 LocalNetworkAccessRestrictionsTemporaryOptOut),请参阅 Google Chrome 限制访问私有主机名以获取后续步骤。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力